Alexandre Borges
@alexandreborges.bsky.social
Vulnerability Researcher | Exploit Developer (speaker 3x at DEF CON)
SPIR-V on ROCm: A Portable IR for AMD GPUs: A follow-up post will discuss a real-world SPIR-V deployment at scale: PyTorch." rocm.blogs.amd.com/software-too... #cybersecurity #informationsecurity #processors #architecture #infosec
FirmBurn: How Firmware Zero‑Day & SCSI PassThru Burned Iran Banks aleeamini.com/firmburn-fir... #cybersecurity #reverseengineering #informationsecurity #firmware #zeroday #exploitation #infosec
CVE-2026-50469 - ProjFS File Delete bad-jubies.github.io/projected-fi... #windows #vulnerability #exploitation #exploit #cve #informationsecurity
SoK: 20 Years of Power, Privilege, and Peril in x86 System Management Mode vanbulck.net/files/woot26... #cybersecurity #smm #platformsecurity #informationsecurity #infosec
Hunting Memory Leaks in bsnmpd with DTrace: oshogbo.com/blog/92/ #dtrace #cybersecurity #informationsecurity #infosec #performance
The work continues... a third vulnerability in just a few days, and like the other two, this one also affects iOS 26.5 and iOS 26.5.2. The challenge, as usual, centers on the next steps for exploitation. #ios #vulnerability #apple
Redis 8.6: Remote Code Execution via Stream PEL Use After Free: zerotistic.blog/posts/redis-... #linux #vulnerability #exploitation #informationsecurity #infosec #cybersecurity
Malwoverview 8.0.5 (Revolutions): github.com/alexandrebor... #cybersecurity #malware #threathunting #informationsecurity #dfir
Dissecting and Exploiting Linux LPE Variant: DirtyClone (CVE-2026-43503): research.jfrog.com/post/dissect... #cve #linux #cybersecurity #informationsecurity #exploitation #vulnerability
A Windows Kernel in a Browser Tab, Part I: Cold Boot, Fast Boot, and Four Megabytes: www.msuiche.com/posts/nanokr... #kernel #infosec #programming #rust #windows #hacking
TrigonLegacy - Deterministic iOS 7-9 tfp0: therealclarity.github.io/blog/trigon-... #ios #apple #exploitation #informationsecurity #cybersecurity #vulnerability #reverseengineering
TrigonLegacy - Deterministic iOS 7-9 tfp0 | Clarity
TrigonLegacy exploits an integer overflow in the VM layer when creating memory entries. This allows arbitrary physical memory read/write, which is then used to build a tfp0 primitive. This exploit ...
therealclarity.github.io
(remember) Introducing usbliter8: ps.tc/pages/blog-u... #cybersecurity #ios #exploitation #exploit #bootrom #iphone #informationsecurity #infosec
Unprivileged root via a use-after-free in DRM GEM change_handle (CVE-2026-46215): cyberstan.co.uk/drm-lpe-linux/ #linux #kernel #vulnerability #cybersecurity #exploitation
Spiteful Fruit - AppleRAID Kernel Heap OOB Write: ret2p.lt/2026/06/30/s... #cybersecurity #informationsecurity #iOS #apple #vulnerability #informationsecurity #infosec #exploitation
Another vulnerability in iOS 26.5 with a clear and reproducible crash, registers control, primitive and PoC confirmed, and possibly a working exploit... who knows... ;)
Zombie COTables: Resurrecting Freed Memory to Escape VirtualBox: blog.exodusintel.com/2026/06/15/z... #vulnerability #exploitation #exploit #virtualbox #cybersecurity #infosec #informationsecurity
Zombie COTables: Resurrecting Freed Memory to Escape VirtualBox - Exodus Intelligence
By Luca Ginex Overview This blog post discusses a use-after-free vulnerability that we found in VirtualBox in 2025. This vulnerability was patched on Oracle Critical Patch Update – January 2026. The v...
blog.exodusintel.com
Malwoverview 8.0.2 has been released: github.com/alexandrebor... To install it: python -m pip install -U malwoverview[all] #malware #threathunting #informationsecurity #infosec #vulnerability #cve #dfir
Bypassing SSL Pinning on Play Store AVDs without Frida www.mfumis.com/posts/bypass... #cybersecurity #informationsecurity #frida #mobiledevice #infosec #mobilesecurity #mobile
Bypassing SSL Pinning on Play Store AVDs without Frida
📲 🔓 Bypassing SSL Pinning on Play Store Android Device Emulators without Frida
mfumis.com
Authenticated RCE via Argument Injection in Gogs (NOT FIXED): www.rapid7.com/blog/post/ve... #cybersecurity #vulnerability #rce #informationsecurity #exploitation
Authenticated RCE via Argument Injection in Gogs (NOT FIXED)
Rapid7 researchers found that Gogs allows authenticated users to achieve RCE on the server by creating a pull request with a specially crafted branch name. More in our latest analysis blog.
rapid7.com
Striga: Lifting x86 to LLVM IR with Python: secret.club/2026/05/21/s... #python #reversing #llvm #informationsecurity #infosec #cybersecurity
GHSL-2026-140: Heap Buffer Write Overflow in 7-Zip (CVE-2026-48095): securitylab.github.com/advisories/G... #vulnerability #cybersecurity #informationsecurity #exploitation #cve
Arbitrary Kernel Address Increment via NtQuerySystemInformation: pwn2nimron.com/blog #vulnerability #informationsecurity #exploitation #cybersecurity #exploit #windows
CVE-2026-28910: Breaking macOS App Sandbox Data Containers, TCC, and Hijacking Apps Using Archive Utility: mysk.blog/2026/05/19/c... #macOS #exploitation #infosec #informationsecurity #vulnerability #cve #exploit
CVE-2026-28910: Breaking macOS App Sandbox Data Containers, TCC, and Hijacking Apps Using Archive Utility
Until macOS 26.4, Archive Utility had nearly unrestricted filesystem access. Combined with a drag-and-drop sandbox quirk, this let an attacker bypass App Sandbox data containers, Transparency, Consent...
mysk.blog
FatGid+4: A four-byte type, an eight-byte stride, one root shell. fatgid.io #vulnerability #exploit #cybersecurity #informationsecurity #freebsd
New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205): (blog) slcyber.io/research-cen... (tool) github.com/assetnote/cp... #cve #vulnerability #cybersecurity #informationsecurity #authentication
New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205) › Searchlight Cyber
Times Are Changing These last few months have been super weird. We've ended up in a situation several times where we have learnt that an exploits life cycle has significantly been reduced due to the i...
slcyber.io
How Kernel Anti-Cheats Work: A Deep Dive into Modern Game Protection: s4dbrd.github.io/posts/how-ke... #reverseengineering #informationsecurity #cybersecurity #game #windows #kernel #debugging